Legal
GDPR
Last updated: August 2026
Fionnglas Tech is based in Ireland and complies with the General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018 in everything we do — both as a business handling enquiry data ourselves, and as a developer building sites that may process data on behalf of our clients.
Data we control directly
Enquiry form submissions, quote requests and reviews left on this website are controlled by us, as described in our Privacy Policy. This covers the personal data of visitors to fionnglastech.com and people who contact us directly.
Data we process for clients
When we build a website, hosting setup or CMS/admin area for a client, that client remains the data controller for any personal data their site collects (for example, their own customers' contact form submissions, bookings or account details). We act as a data processor in that relationship, and process data only as instructed, using security practices consistent with GDPR requirements — including CSRF protection on forms, prepared statements against SQL injection, and a Content-Security-Policy on every build.
Data protection by design
Every site we build follows the same baseline practices:
- Passwords are hashed, never stored in plain text.
- Admin areas are session-protected with brute-force login throttling.
- Personal data submitted through forms is only collected where there's a clear purpose for it.
- Nothing submitted through a public form (enquiries, reviews) is published automatically — it's reviewed by an administrator first.
- Sites are built to support a cookie consent banner and to keep third-party analytics scripts off until consent is given.
Data Processing Agreements
If your project requires a formal Data Processing Agreement (DPA) — for example, because the site will handle sensitive personal data or serve customers outside Ireland — let us know as part of your project scope and we'll put one in place before development starts.
International transfers
We host projects on Irish/EU-based infrastructure by default. Where a project uses a third-party service that transfers data outside the EEA (for example, a US-based analytics or email tool), we'll flag this as part of the build so you can make an informed decision.
Your rights and how to exercise them
See our Privacy Policy for the full list of your rights as a data subject, and how to contact us to exercise them. You can also complain to the Irish Data Protection Commission at dataprotection.ie at any time.
Contact
For any data protection question relating to this website or a project we've built, email PLACEHOLDER — hello@fionnglastech.com.